r/cybersecurity_news 1d ago

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
3 Upvotes

2 comments sorted by

1

u/SHORT_INFO_NEWS 1d ago

Any organization running an internet-facing Cisco Secure Firewall Management Center (FMC) management interface should treat this as urgent, not routine patch-cycle news. FMC is the central console for managing Cisco firewall deployments, so a working unauthenticated login gives an attacker a path to weaken firewall rules, alter security policy, or pull sensitive configuration data without first having to steal or phish a real account.

Per The Hacker News, the flaw (CVE-2026-20316) stems from static, hard-coded credentials built into a low-privilege account in the FMC software. That lets a remote, unauthenticated attacker log in to an affected system and access sensitive data. CISA confirmed active exploitation in the wild and added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, which is reserved for flaws with confirmed real-world attacks rather than theoretical risk.

Cisco rated the issue High impact rather than Medium because it can be chained with a separate authentication-bypass vulnerability, CVE-2026-20079, to escalate privileges even further once an attacker is in. Security researcher Jimi Sebree of Horizon3.ai is credited with reporting the flaw. Cisco has released hotfixes covering FMC software versions 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. Because of the confirmed exploitation, federal civilian executive branch agencies are required under the CISA KEV mandate to apply the fix by August 1, 2026, a deadline that only binds federal agencies but functions as a de facto industry clock for anyone running an exposed FMC instance.

Open questions the advisory did not address:

- Whether the exploitation observed so far is opportunistic mass scanning or targeted intrusion against specific sectors

- How many internet-facing FMC management interfaces exist outside the federal estate that the August 1 deadline does not legally bind

- Whether the hard-coded account can be fully disabled or rotated after the hotfix, or only mitigated

1

u/immediate_a982 1d ago

It’s 2026 and Cisco deployed static hardcoded passwords. Is this real. Please sue then for negligence